Privacy Policy
Last updated: October 7, 2026
The Giraffe Company ("Giraffe", "we", "us") is a Canadian company. This policy explains what personal information we collect through this website and through the Giraffe marketing platform, including information we receive from Google APIs, and what we do with it. We handle personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and other privacy laws that apply.
1. Who we are and how to reach us
The Giraffe Company, Ontario, Canada.
Privacy questions and requests: privacy@thegiraffecompany.ca.
We aim to answer within 30 days.
2. Information from this website
Inquiry forms. When you book a demo, send an enquiry, or ask about a talk or workshop, we collect what you enter: your name, email address and, if you give it, your phone number; then details about your business or event (for example your business name, the kind of business, the number of locations and your website, or your organization, event date, format and audience) and any message. We save your name, email and phone number as soon as you continue past the first step, so we can reply even if you don't finish the form. We use this information to reply to you, to decide whether we're a good fit, and to follow up about that request. If you tick the box on the form, we'll also send you occasional emails about Giraffe, and you can unsubscribe at any time. We don't sell it or use it for anyone else's marketing.
Email. If you email us directly, we keep the correspondence to respond and for our business records.
Site analytics. We use Plausible Analytics to count visits and see which pages are read. Plausible does not use cookies and does not collect information that identifies you personally. We do not use advertising or retargeting cookies on this site.
3. The Giraffe platform and Google user data
The Giraffe platform is the software our staff use to deliver marketing services to our clients (see Platform). Part of it connects to Google APIs. Only Giraffe staff sign in to it, with their own Google accounts, and only to work on Google Analytics, Google Tag Manager and Google Ads accounts that belong to our clients or that we hold on their behalf.
What we access, by permission:
| Google service | Permission requested | What we use it for |
|---|---|---|
| Google account | Your email address and basic profile (openid, userinfo.email) | To identify which staff member signed in. |
| Google Analytics | View and manage Analytics data (analytics.edit, analytics.readonly) | To create and configure clients' Analytics accounts and properties (data streams, key events, conversions) and to read their reports. |
| Google Analytics | Manage users (analytics.manage.users) | To grant and remove access to clients' Analytics accounts for the client's and our team members. This involves those people's email addresses. |
| Google Marketing Platform | View and link Analytics accounts (marketingplatformadmin.analytics.read, .update) | To link clients' Analytics accounts to our Google Marketing Platform organization. |
| Google Tag Manager | View, edit and publish containers (tagmanager.readonly, tagmanager.edit.containers, tagmanager.edit.containerversions, tagmanager.publish) | To create a Tag Manager container for a client's website and publish our standard measurement setup. |
| Google Ads | Manage Google Ads accounts (adwords) | To read campaign performance (impressions, clicks, cost, conversions, search terms) and to create and configure campaigns, conversions and audiences for clients who have asked us to run their ads. We do not access billing or payment information. |
What that data is. Mostly configuration and reporting about our clients' businesses: account and property settings, tag configurations, and aggregated website and advertising statistics. Google Analytics reports describe website visitors in aggregate (for example counts by page, source, region or device); they do not tell us who an individual visitor is. Personal information we do handle includes the email addresses of the people who have access to a client's accounts, and the signed-in staff member's Google email.
How we use it. Only to set up, run, measure and report on marketing for the client that the account belongs to. We do not use Google user data for advertising, do not sell it, do not use it to build profiles of individuals, and do not use it for any purpose unrelated to that client's work.
We do not use Google user data to develop, improve or train generalized AI or machine-learning models. Where the platform uses AI services to help write reports, it does so under terms that do not allow the provider to train on our data.
4. Storage and security
Information from this website and the platform is stored on Google Cloud. Our website, application and database run in Google Cloud's Montréal region; analytics exports are stored in Google BigQuery. As a result, personal information may be stored and processed in Canada and the United States, where it may be accessible to authorities under those countries' laws.
We protect it with encryption in transit and at rest, access limited to staff who need it for their work, and Google-managed service accounts rather than shared passwords for the platform's automated reporting. Google sign-in tokens are held only for the staff member who granted them.
5. Google API Services: Limited Use
The Giraffe Company's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Sharing
We don't sell personal information. We share it only:
- With the client it belongs to. Reports and dashboards built from a client's Google data go to that client.
- With service providers who run parts of our service for us, under contract and only for that purpose: Google Cloud (hosting, storage), our email delivery provider, Plausible (website analytics) and AI service providers used to draft content and reports.
- When the law requires it, or to protect our rights or someone's safety.
- In a business transfer, such as a merger or sale, to a successor bound by this policy.
We do not transfer Google user data to anyone else, except as needed for the purposes above, to comply with law, or as part of a merger or acquisition.
7. Retention
- Inquiries and email: as long as needed to respond and for our business records, then deleted, and no longer than 3 years after our last contact unless you become a client.
- Google data in the platform: copies of responses from Google APIs are kept for up to 400 days so reports can be rebuilt; near-real-time activity updates for 90 days; daily reporting figures for up to 25 months.
- When a client relationship ends, we stop accessing that client's Google accounts and delete their Google data from the platform within 90 days, unless the client asks us to keep it or the law requires us to.
8. Revoking access and your choices
- Revoke the platform's Google access. Any Google account that signed in to the platform can remove it at any time at myaccount.google.com/permissions.
- Remove us from a Google account. A client can remove The Giraffe Company (including our manager account or service account) from the Users / Access management settings in Google Analytics, Tag Manager or Google Ads, or ask us to do it.
- Delete your data. Email us at the contact address above to ask us to delete data we hold about you or your accounts. We'll confirm when it's done.
9. Your rights
You may ask to see the personal information we hold about you, correct it, or withdraw your consent to its use (which may limit what we can do for you). Ask using the contact address above. If you're not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca).
10. Changes
We'll post any change to this policy on this page and update the date at the top. If a change materially affects how we use Google user data, we'll tell affected clients before it takes effect.